Splunk Enterprise

Powershell scripted input debug logging


Does anyone know how to log INFO and WARN log_level events to $SplunkHome\var\log\splunk\splunk-powershell.ps1.log or $SplunkHome\var\log\splunk\splunkd.log for debug purposes using the powershell input?

Using the code below in the script terminates it:


Write-Error -Message 'INFO test'




10-16-2020 12:47:05.4859538-5 ERROR Executing script=& "$SplunkHome/etc/apps/foo/bin/foo.ps1" for stanza=foo failed with exception=INFO test


The script does run correctly. I would just like to have some debug options. Thanks. 

Labels (1)
Tags (3)
0 Karma


Did you ever work this out? I've tried Write-Warning, but the output didn't go into the log or into the indexed output

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.